2018 CVE Vulnerabilities
17,817 CVEs published in 2018.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-12475 | MEDIUM | 5.4 | 0.6% | Sep 1, 2020 | A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUS... |
| CVE-2018-1985 | MEDIUM | 4.4 | 0.3% | Aug 24, 2020 | IBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privi... |
| CVE-2018-21256 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for... |
| CVE-2018-21252 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail a... |
| CVE-2018-21265 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRe... |
| CVE-2018-21261 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the ... |
| CVE-2018-21259 | MEDIUM | 5.3 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of s... |
| CVE-2018-21257 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for... |
| CVE-2018-21255 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to mod... |
| CVE-2018-21254 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-mess... |
| CVE-2018-21253 | MEDIUM | 4.3 | 0.6% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slas... |
| CVE-2018-21250 | MEDIUM | 6.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a deni... |
| CVE-2018-16848 | MEDIUM | 6.5 | 1.2% | Jun 15, 2020 | A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a... |
| CVE-2018-21243 | MEDIUM | 6.5 | 0.9% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used. |
| CVE-2018-21239 | MEDIUM | 5.3 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR ... |
| CVE-2018-21237 | MEDIUM | 5.3 | 0.8% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action. |
| CVE-2018-18625 | MEDIUM | 6.1 | 1.2% | Jun 2, 2020 | Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an... |
| CVE-2018-18624 | MEDIUM | 6.1 | 1.4% | Jun 2, 2020 | Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an ... |
| CVE-2018-18623 | MEDIUM | 6.1 | 1.8% | Jun 2, 2020 | Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for ... |
| CVE-2018-8956 | MEDIUM | 5.3 | 3.1% | May 6, 2020 | ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchron... |
| CVE-2018-21233 | MEDIUM | 6.5 | 0.5% | May 4, 2020 | TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the co... |
| CVE-2018-21232 | MEDIUM | 5.5 | 1.4% | Apr 29, 2020 | re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags. |
| CVE-2018-21225 | MEDIUM | 6.8 | 0.8% | Apr 28, 2020 | Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, ... |
| CVE-2018-21209 | MEDIUM | 4.8 | 0.7% | Apr 28, 2020 | Certain NETGEAR devices are affected by reflected XSS. This affects JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, J... |
| CVE-2018-21201 | MEDIUM | 6.8 | 0.6% | Apr 28, 2020 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor... |
Check if your code is affected by 2018 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now